The DIVD, a nonprofit bug hunting organization, disclosed on Thursday that attackers broke into its IT system on September 21 using two zero-day vulnerabilities in Zammad, an open-source helpdesk and customer support ticketing system. The chained exploits allowed the attackers to hijack sessions, execute remote code as the local Zammad user, and escalate privileges to root.
The bugs have been assigned CVE-2026-102489 and CVE-2026-102490, both with a CVSS 4.0 score of 9.4 in the chained attack scenario. CVE-2026-102489 enables unauthenticated remote code execution and session leakage, affecting Zammad versions 6.3.0 to 6.5.4 and 7.0.0 through 7.1.3 (though not exploitable in version 7 due to environment conditions). CVE-2026-102490 allows a local user to gain root privileges and affects all Zammad versions. DIVD advises users to upgrade to version 7 or take the system offline.
DIVD discovered the breach the following day, blocked access to all data center systems, and formed an incident response team with Merlon Security. On September 24, it reported the vulnerability to Zammad's vendor, notified the Dutch Data Protection Authority and the National Cyber Security Centre, and discussed options with police. The organization also posted its first disclosure on LinkedIn, stating: "It took us (almost) seven years but we can now say that we're the hackers that got hacked." DIVD said it remains committed to handling the incident openly and transparently, "even if it sucks."
DIVD noted that its team had never seen an attack like this before, with the modus operandi indicating an agentic AI powered attack. "We could see the agent working automated, because after every action it decided the next step itself, at the speed of light and sloppy logic or pattern," the organization said in a subsequent post. Logs revealed embedded notes in the attack script, where the AI justified its actions in code comments. "What human attacker leaves notes to themself in their scripts, explaining why what they're doing is okay and really not phishing? The AI just got a task and keeps justifying its own actions in the code as comments, a human wouldn't care less," the post added.
The stolen data includes DIVD email addresses and potentially other contact details. "We're still investigating exactly which data of which volunteers is affected," DIVD said in its incident report. The organization warned volunteers of a higher risk of social engineering, as attackers could more easily pose as DIVD members. It advised anyone receiving a suspicious email or contact request from someone claiming to be from DIVD to verify by emailing communications@divd.nl.